CVE-2017-1000117
HIGH 8.8EPSS 77.8%
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.
- CVSS v3.0
- 8.8 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 77.82% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2017-10-04
- Updated
- 2024-08-05
Proof-of-concept exploits (22)
- AnonymKing/CVE-2017-10001173★ · 2019-06-21
- Jerry-zhuang/CVE-2017-10001170★ · 2021-08-11
- Manouchehri/CVE-2017-100011715★ · 2017-08-11
- Q2h1Cg/CVE-2017-10001170★ · 2017-12-03
- Shadow5523/CVE-2017-1000117-test0★ · 2017-08-18
- VulApps/CVE-2017-10001173★ · 2017-08-12
- alilangtest/CVE-2017-10001170★ · 2017-08-12
- chu1337/CVE-2017-10001170★ · 2017-12-03
- cved-sources/cve-2017-10001170★ · 2021-04-15
- greymd/CVE-2017-1000117136★ · 2017-08-16
- ieee0824/CVE-2017-10001174★ · 2017-08-16
- ieee0824/CVE-2017-1000117-sl0★ · 2017-08-16
- ikmski/CVE-2017-10001170★ · 2017-08-17
- leezp/CVE-2017-10001171★ · 2019-05-20
- nkoneko/CVE-2017-10001172★ · 2021-10-29
- rootclay/CVE-2017-10001170★ · 2017-08-16
- sasairc/CVE-2017-1000117_wasawasa1★ · 2017-08-15
- siling2017/CVE-2017-10001170★ · 2017-09-04
- takehaya/CVE-2017-10001170★ · 2017-08-17
- thelastbyte/CVE-2017-10001170★ · 2017-09-01
- timwr/CVE-2017-10001177★ · 2017-08-11
- wuhao939/vulhub0★ · 2019-05-01